Secure Terminal Trusted Execution Environment Command Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems used in infrastructure and industrial applications are vulnerable to malicious attacks due to compromised host devices transmitting unsolicited commands, and firewalls are not effective in preventing such threats as they can be susceptible to bugs that allow attackers to bypass security measures.
Innovation Solution
A secure terminal configured with a trusted execution environment (TEE) and trusted peripheral devices is used to verify the integrity of commands from host devices, implementing policies to filter and authorize transmissions, ensuring only authorized instructions are forwarded to remote devices, and utilizing cryptographic and physical security to protect the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewalls are used to protect from malicious attacks, then network security is improved, but firewalls are susceptible to bugs that allow attackers to bypass security measures
Solution Approach 1:
The patent introduces a secure terminal as an intermediary device positioned between the host device and the network. This secure terminal verifies the integrity of commands before they are transmitted, acting as a mediator that prevents compromised commands from reaching the network. The secure terminal includes a trusted execution environment that cryptographically verifies command integrity, thereby addressing the firewall's vulnerability to bypass attacks while maintaining network security.
Solution Approach 2:
The patent implements preliminary verification of command integrity before commands are transmitted to the network. The secure terminal performs cryptographic verification using trusted execution environments to ensure commands have not been compromised by malware. This preliminary action prevents potentially malicious commands from ever reaching the network, addressing the reliability issue by catching threats before they can exploit firewall vulnerabilities.
2Reliability
If secure terminal with TEE is used to verify command integrity, then system security is improved, but device complexity increases
Solution Approach 1:
The patent implements a nested architecture where the trusted execution environment (TEE) is embedded within the secure terminal, which itself is embedded within the broader industrial control system. The TEE is a specialized processing environment nested within the secure terminal's hardware, providing cryptographic verification capabilities. This nesting allows the complex security functions to be contained within a dedicated subsystem, managing overall system complexity while enhancing command integrity verification.
Data Source
AI summary
A secure terminal configured to support a trusted execution environment that utilizes policy enforcement to filter and authorize transmissions received from a host device and destined for a remote device. Upon receiving a transmission from the host device, the secure terminal verifies that the instruction, message, or request contained within the transmission satisfy parameters set by a policy. If the transmission satisfies the parameters, then the secure terminal signs the transmission with a key unique to the trusted platform module associated with the secure terminal and forwards the signed transmission to the remote device. If the transmission fails one or more parameters within the policy, a message that details the instruction or operation contained within the transmission is exposed to a user at an output device, in which the user can authorize or reject the transmission using an input device.


